Re: Dabase BAcked IPTables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The internet works on IP not on mac....
it's like "I want to buy a car who don't move"
OK NP just buy something else then a car...

ipset is the tool and you would need couple security levels in order to prevent spoofing and defending aginst Some malicious attempts on this site..

Eliezer

On 06/29/2013 04:21 AM, Nick Khamis wrote:
Ooops, I realized how many blanks I am leaving in my messages. The
website is only used to allow the user to enter their mac address in
order to have access to our services (not HTTP).

Yes, ./iptables.sh is the ruleset script.

When you update your ipset, any rule referring to that set uses the
new set right away. There would be no point in dumping and then
reloading your ruleset.

Hmm, this covers adding *new* mac or even ip addresses however, how
would delete/modify existing entries dynamically.

Kind Regards.

Nick.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux